CVE-2021-1871: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
A flaw was found in WebKitGTK.
Impact: A remote attacker may be able to cause arbitrary code execution. Description: A logic issue was addressed with improved restrictions.
Reference: https://webkitgtk.org/security/WSA-2021-0003.html
Other sources
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
WebKit. A logic issue was addressed with improved restrictions.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.36.4-1~deb10u1Fixed in 2.38.6-0+deb10u1Fixed in 2.40.5-1~deb11u1Fixed in 2.42.1-1~deb11u2Fixed in 2.40.5-1~deb12u1Fixed in 2.42.1-1~deb12u1Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1Fixed in 2.38.6-1Fixed in 2.42.1-1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.32.0 - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Patch Security Update 2021-001 - Upgrade
Upgrade
macOS Mojaveto a version that resolves this vulnerability.Patch Security Update 2021-001 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.36.4-1~deb10u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.38.6-0+deb10u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.5-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-1~deb11u2 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.5-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.1-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-1761
- CVE-2021-1797
- CVE-2020-27945
- CVE-2021-1760
- CVE-2021-1747
- CVE-2021-1776
- CVE-2021-1759
- CVE-2021-1772
- CVE-2021-1792
- CVE-2021-1787
- CVE-2021-1786
- CVE-2020-27937
- CVE-2021-1802
- CVE-2021-1791
- CVE-2021-1790
- CVE-2021-1775
- CVE-2020-29608
- CVE-2021-1758
- CVE-2021-1783
- CVE-2021-1741
- CVE-2021-1743
- CVE-2021-1773
- CVE-2021-1778
- CVE-2021-1736
- CVE-2021-1785
- CVE-2021-1766
- CVE-2021-1818
- CVE-2021-1742
- CVE-2021-1746
- CVE-2021-1754
- CVE-2021-1774
- CVE-2021-1777
- CVE-2021-1793
- CVE-2021-1737
- CVE-2021-1738
- CVE-2021-1744
- CVE-2021-1779
- CVE-2021-1757
- CVE-2020-27904
- CVE-2021-1764
- CVE-2021-1782
- CVE-2021-1750
- CVE-2020-29633
- CVE-2021-1781
- CVE-2021-1771
- CVE-2021-1762
- CVE-2020-29614
- CVE-2021-1763
- CVE-2021-1767
- CVE-2021-1745
- CVE-2021-1753
- CVE-2021-1768
- CVE-2021-1751
- CVE-2020-25709
- CVE-2020-27938
- CVE-2019-20838
- CVE-2020-14155
- CVE-2020-15358
- CVE-2021-1769
- CVE-2021-1788
- CVE-2021-1765
- CVE-2021-1801
- CVE-2021-1789
- CVE-2021-1871
- CVE-2021-1870
- CVE-2021-1799
- CVE-2021-30869
- CVE-2021-1794
- CVE-2021-1795
- CVE-2021-1796
- CVE-2021-1780
- CVE-2021-1838
- CVE-2021-1748
- CVE-2021-1756
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-1871.
What is the title of this vulnerability?
The title of this vulnerability is Apple iOS iPadOS and macOS Remote Code Execution Vulnerability.
Which software is affected by this vulnerability?
Apple iOS, iPadOS, and macOS are affected by this vulnerability.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability to execute code.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found on the Apple support website: [link](https://support.apple.com/en-us/HT212147) and [link](https://support.apple.com/en-us/HT212146).